partnership-research
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill researches external entities by ingesting data from LinkedIn profiles, posts, and web search results. This external content is untrusted and could contain malicious instructions designed to influence the agent's synthesis or subsequent actions.
- Ingestion points: Data retrieved from
linkedin_web_v2_company_posts,exa_search, andtavily_searchviasandbase_call_toolinSKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or "ignore embedded instructions" warnings for external tool output.
- Capability inventory: The skill uses
sandbase_call_toolto interact with external research and enrichment APIs. - Sanitization: There are no instructions for sanitizing, escaping, or validating the content retrieved from external sources before interpolation into the agent's response context.
Audit Metadata